Use the Commbroker Configuration area in the Evidence Collector page to add the input module or to delete the input module from the Comm Broker configuration using the Web UI.
In the following example, the Network Security appliance does not yet contain the input modules for Comm Broker.
.png)
You specify the following information about the input module.
Field | Description |
|---|---|
Input Type | The input format type (syslog or JSON) for the Comm Broker module. |
Interface | Events sent over TCP, UDP, or SSL are received on the ether1 or ether2 management interface.
|
Protocol | The protocol (TCP, UDP, or SSL) that is used by Comm Broker to receive the incoming syslog and JSON events. |
Port | The port number that is used by Comm Broker to receive third-party syslog and JSON events. |
To add an input module to the Communications Broker Sender configuration:
In the Web UI, choose Settings > Evidence Collector.
Click Helix Integration.
In the Input Type drop-down list, choose syslog or JSON input format.
In the Interface drop-down list, choose ether1 or ether2 management interface.
In the Protocol drop-down list, choose TCP, UDP, or SSL to receive the incoming syslog and JSON events.
In the Port field, enter the port number that is used by Comm Broker to receive the third-party syslog and JSON events. Valid values are integers ranging from 514 to 65535.
Click Add.
The input module is added to the Comm Broker configuration. The following message appears:
.png)
An error is displayed if you did not specify a valid port number.
To delete an input module from the Communications Broker Sender configuration:
In the Web UI, choose Settings > Evidence Collector.
Click Helix Integration.
.png)
In the table, locate the input module you want to delete.
Click the trash can icon in the Action column. A confirmation dialog box appears.
.png)
Click Yes to confirm that you want to delete the input module from the Comm Broker configuration.
The input module is deleted from the Comm Broker configuration. The following message appears:
.png)